CVE-2025-13476: Rakuten Viber

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327)

Affected products

  • Rakuten Viber: from 25.6.0, up to and including 25.8.1.0; version 9.3.0.6 only

Published 2026-03-05. Last modified 2026-06-17.